<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Technoblog.org &#187; 10.5</title>
	<atom:link href="http://technoblog.org/tag/105/feed/" rel="self" type="application/rss+xml" />
	<link>http://technoblog.org</link>
	<description>Technoblogging</description>
	<lastBuildDate>Tue, 12 Apr 2011 11:47:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Trend Micro OfficeScan 10.5 Features and thoughts</title>
		<link>http://technoblog.org/2010/10/trend-micro-officescan-10-5-features-and-thoughts/</link>
		<comments>http://technoblog.org/2010/10/trend-micro-officescan-10-5-features-and-thoughts/#comments</comments>
		<pubDate>Mon, 11 Oct 2010 08:32:53 +0000</pubDate>
		<dc:creator>jrp</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[10.5]]></category>
		<category><![CDATA[OfficeScan 10.5]]></category>
		<category><![CDATA[Trend Micro OfficeScan 10.5]]></category>

		<guid isPermaLink="false">http://technoblog.org/?p=115</guid>
		<description><![CDATA[It’s almost 2 months since the release of OfficeScan 10.5. Anyone out there upgraded yet? If so, what’s your experience? I&#8217;ve done a couple of installations and upgrades, and I&#8217;ll share my experiences: First, what’s changed in OfficeScan from version 10.0 SP1? - Active Directory Integration - Smart Protection Solutions - Security Compliance - Virtual [...]]]></description>
			<content:encoded><![CDATA[<p>It’s almost 2 months since the release of OfficeScan 10.5. Anyone out there upgraded yet? If so, what’s your experience?<br />
I&#8217;ve done a couple of installations and upgrades, and I&#8217;ll share my experiences:</p>
<p>First, what’s changed in OfficeScan from version 10.0 SP1?</p>
<p>- Active Directory Integration<br />
- Smart Protection Solutions<br />
- Security Compliance<br />
- Virtual Desktop Support<br />
- Role-based administration<br />
- General Product enhancements</p>
<p>So, what is my experience with the new features?<br />
<span id="more-115"></span><br />
<strong>Active Directory Integration</strong><br />
Closer integration with active directory. Personally not tested.</p>
<p><strong>Smart Protection Solutions</strong><br />
I guess this is enhancements to the file reputation and the implementation of a &#8220;local&#8221; web reputation server.<br />
Tested this one, works fine. Good idea to include a local alternative, instead of having all your clients talk to &#8220;the cloud&#8221;. The new version of the TMCSS (Cloud Scan Server) also works with OfficeScan 10.0 SP1.</p>
<p>You can either perform a fresh install, or upgrade from 1.x.</p>
<p><strong>Security Compliance</strong><br />
Not tested.</p>
<p><strong>Virtual Desktop Support</strong><br />
According to Trend, OfficeScan is now &#8220;VDI&#8221;-aware. And supports VMware View 4 and Citrix XenDesktop 4.<br />
Anyone running those products tested?</p>
<p><strong>Granular Role-based Administration</strong><br />
Pretty much standard role based administration, with the possibility to use Active Directory user accounts. Also single sign on support.</p>
<p><strong>General Product enhancements</strong><br />
Just a bunch of smaller product enhancements.</p>
<p>They fixed stuff related to:<br />
- Update Agent<br />
- Exception list<br />
- Firewall<br />
- Logs<br />
- Scan Settings<br />
- Web Reputation<br />
- Plug in program updates</p>
<p><strong>Update Agent</strong><br />
You can now have update agents separately download components, settings and program updates. A new report tool for update agents has also been implemented.</p>
<p><strong>Exception list</strong><br />
There are now separate lists for Behavior Monitoring and Device control exceptions. In 10.0 they were the same.</p>
<p><strong>Firewall</strong><br />
It is now possible to make exceptions for software on the Certified Software List, or block specific applications.</p>
<p>Also, when installing OfficeScan server from scratch, you will be asked if you want to enable the OfficeScan firewall, AND if you want to enable the firewall for server platforms. Earlier, if you enabled the firewall, it would be enabled both for workstations/laptops AND servers. This is great, because the firewall is not recommended for server platforms, but for client platforms. So you can get away with just one OfficeScan server (if you want to). In other words, no need to have dedicated server without the firewall enabled. You might of course still want to do this, so you can patch the client server, separate from the server server (server server server? <img src='http://technoblog.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ).</p>
<p><strong>Logs</strong><br />
Enhancements of the logging feature will ensure consistency between time settings on OfficeScan clients, server and Control Manager. In other words &#8220;unified time stamping&#8221;.</p>
<p><strong>Scan Settings</strong><br />
The following configuration options are now available on the local client (as long as the client has privileges to configure scan exclusions):<br />
- Add, remove or overwrite files and directories from the client scan exclusion list.<br />
- configure OLE exploit detection settings<br />
- Configure settings for action on probable virus malware (scan actions on heuristic and generic detection)<br />
- Clean Spyware/grayware in zipped files setting<br />
- Use wildcards in the scan exclusion lists.</p>
<p>They also added additional options in the web gui. These are not listed in the release notes. But I&#8217;ve found some of them, and the most important one is the option to configure actions on generic/heuristic while using Active Action.<br />
But I&#8217;m bit confused, since this is not an option if you use &#8220;use the same actions for all&#8221;.<br />
Even if you configure the same actions for all types, you will have to specify &#8220;1st&#8221; and &#8220;2nd&#8221; scan action in the ofcscan.ini file.</p>
<p>As far as I know OfficeScan will still &#8220;Pass&#8221; potential security threats, if not configured with &#8220;1st&#8221; and &#8220;2nd&#8221; action when using the same actions for all types.</p>
<p><strong>Web reputation settings</strong><br />
You can now configure web reputation policies and assign them to one, multiple or all OfficeScan clients.</p>
<p><strong>Plug in program updates</strong><br />
OfficeScan can now automagically download plug in program updates from the first source in the server update source list. This includes Trend Micro Control Manager.</p>
<p>So, except from the GUI-bug mentioned in an earlier <a href="http://technoblog.org/2010/10/trend-micro-officescan-10-5-scan-exclusion-bug/">post</a>, it should be safe to upgrade to version 10.5. I have not experienced any other problems. Have you?</p>
]]></content:encoded>
			<wfw:commentRss>http://technoblog.org/2010/10/trend-micro-officescan-10-5-features-and-thoughts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trend Micro OfficeScan 10.5 Scan Exclusion Bug</title>
		<link>http://technoblog.org/2010/10/trend-micro-officescan-10-5-scan-exclusion-bug/</link>
		<comments>http://technoblog.org/2010/10/trend-micro-officescan-10-5-scan-exclusion-bug/#comments</comments>
		<pubDate>Wed, 06 Oct 2010 10:21:02 +0000</pubDate>
		<dc:creator>jrp</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[10.5]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[hotfix]]></category>

		<guid isPermaLink="false">http://technoblog.org/?p=113</guid>
		<description><![CDATA[If you have upgraded to OfficeScan 10.5, and are experiencing problems with scan exclusions, it might be because your scan exclusion list exceeds 1000 characters. If it does, it might cause the OfficeScan Master Service or the DBServer to crash. This is a known issue! Ask your Trend Micro Partner/Reseller for Hotfix 1106.1]]></description>
			<content:encoded><![CDATA[<p>If you have upgraded to OfficeScan 10.5, and are experiencing problems with scan exclusions, it might be because your scan exclusion list exceeds 1000 characters. If it does, it might cause the OfficeScan Master Service or the DBServer to crash.</p>
<p>This is a known issue! Ask your Trend Micro Partner/Reseller for Hotfix 1106.1 </p>
]]></content:encoded>
			<wfw:commentRss>http://technoblog.org/2010/10/trend-micro-officescan-10-5-scan-exclusion-bug/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Mac OS X DNS workaround failed</title>
		<link>http://technoblog.org/2008/08/mac-os-x-dns-workaround-failed/</link>
		<comments>http://technoblog.org/2008/08/mac-os-x-dns-workaround-failed/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 23:22:16 +0000</pubDate>
		<dc:creator>jrp</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[10.4]]></category>
		<category><![CDATA[10.5]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[Client]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[mac os x]]></category>
		<category><![CDATA[random source port]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Security Update 2008-005]]></category>

		<guid isPermaLink="false">http://technoblog.org/?p=12</guid>
		<description><![CDATA[The latest Mac OS X security update (2008-005) failed to fix (or temporarily solve) the DNS vulnerability in the client version of Mac OS X 10.5 and 10.4. The update solved (temporarily) the same problem in Mac OS X server, but somehow Apple forgot to update the client libraries. The source port is still not [...]]]></description>
			<content:encoded><![CDATA[<p>The latest Mac OS X security update (<a title="Mac OS X Security Update" href="http://technoblog.org/2008/08/mac-os-x-security-update/">2008-005</a>) failed to fix (or temporarily solve) the DNS vulnerability in the client version of Mac OS X 10.5 and 10.4. The update solved (temporarily) the same problem in Mac OS X server, but somehow Apple forgot to update the client libraries. The source port is still not randomized (but incremented by 1 each time). So, is this really a critical problem? Or should we worry more about DNS servers behind NAT?</p>
<p>Read more details about how <a title="DNS Workaround failed Mac OS X 10.5" href="http://isc.sans.org/diary.html?storyid=4810">the DNS workaround failed in Mac OS X 10.5</a> or how the <a title="DNS Workaround failed Mac OS X 10.4" href="http://blog.ncircle.com/blogs/sync/archives/2008/08/apple_dns_patch_fails_to_rando.html">DNS Workaround Failed in Mac OS X 10.4</a></p>
]]></content:encoded>
			<wfw:commentRss>http://technoblog.org/2008/08/mac-os-x-dns-workaround-failed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

